Lead, Incident Operations
JetBlueAbout the role
Position Summary:
At JetBlue, cyber security operates across a complex IT environment, encompassing traditional data centers, Software as a Service (SaaS) services, multiple cloud providers, e-commerce platforms, and a diverse end-user environment.
We are seeking an Incident Operations Lead to support the Cyber Security Incident Response function through incident coordination, stakeholder communication, readiness, documentation, and post-incident follow-through. The ideal candidate is security-fluent, highly organized, comfortable operating during high-pressure events, and able to translate technical findings into clear actions and leadership-ready updates.
This role works closely with technical Incident Response analysts, but is focused on continuous improvement of and leading the operational execution of Incident Response and supporting the technical investigators.
Essential Responsibilities:
- Lead the operational coordination of cybersecurity incidents, including bridge management, stakeholder communication, action tracking, handoffs, documentation, and leadership-ready status updates.
- Coordinate response activity across Incident Response, Threat Intelligence, Detection Engineering, Security Monitoring, IT Operations, Identity, Infrastructure, application teams, Legal, Communications, vendors, and other stakeholders as needed.
- Support incident declaration, escalation, severity alignment, communication cadence, and response workflow execution in accordance with established incident response procedures.
- Translate technical findings, timelines, risks, containment actions and remediation status into clear summaries for leadership and non-technical stakeholders.
- Maintain accurate incident records, including timelines, key decisions, attendees, action items, evidence references, follow-up owners, and closure documentation.
- Drive post-incident follow-through by converting lessons learned, gaps, and corrective actions into tracked issues with owners, due dates, updates, and closure evidence.
- Identify gaps in incident readiness, including access, tooling, logging, escalation paths, contact lists, documentation, playbooks, templates, evidence handling, and cross-team dependencies.
- Develop, maintain, and improve incident response procedures, bridge guidance, communication templates, after-action processes, tabletop materials, and response readiness documentation.
- Coordinate tabletop exercises, readiness reviews, control tests and follow-up tracking to improve the organization’s ability to respond to cybersecurity incidents.
- Support operational prioritization during high-volume periods or active incidents by helping organize response activity, reduce coordination friction, and maintain visibility into outstanding work.
- Provide guidance to analysts and stakeholders on incident documentation, communication expectations, escalation hygiene, and action tracking during response activities.
- Other duties as assigned.
Minimum Experience and Qualifications:
- Bachelor’s Degree in Cyber Security, Information Technology, Computer Science, Business, Emergency Management, or other relevant discipline; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience in cyber security operations, incident response, technology incident management, enterprise IT operations, or a related field.
- Four (4) years of experience coordinating or supporting cybersecurity incidents, technology incidents, security operations, or similar high-priority operational response activities.
- Demonstrated security fluency, including the ability to understand incident response concepts, common security events, severity/risk, containment, remediation, evidence handling, and escalation needs.
- Experience managing incident calls, operational bridges, action trackers, status updates, stakeholder communications, or cross-team response coordination.
- Strong written and verbal communication skills, including the ability to summarize complex technical information clearly for technical and non-technical audiences.
- Ability to organize ambiguous information into clear priorities, owners, actions, timelines, risks, and decisions during time-sensitive events.
- Ability to work effectively with technical responders without micromanaging investigation steps, while ensuring response activity remains structured, documented, and moving forward.
- Strong problem-solving, judgment, ownership, and follow-through skills in a fast-paced operational environment.
- Ability to manage multiple priorities, stakeholders, issues, and deadlines at once.
- Ability to pas
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s